ESET APT Activity Report Q4 2023βQ1 2024
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2023-q1-2024/
π@malwr
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2023-q1-2024/
π@malwr
Welivesecurity
ESET APT Activity Report Q4 2023βQ1 2024
This report summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from October 2023 until the end of March 2024.
MICROSOFT SECURITY BULLETIN COVERAGE FOR MAY 2024
Overview Microsoftβs May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoftβs security advisories for the month of
https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/
π@malwr
Overview Microsoftβs May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoftβs security advisories for the month of
https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/
π@malwr
Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft
https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/
π@malwr
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft
https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/
π@malwr
Welivesecurity
Ebury is alive but unseen: 400k Linux servers compromised for cryptotheft and financial gain
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft.
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices
Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as UTA...
https://www.volexity.com/blog/2024/05/15/detecting-compromise-of-cve-2024-3400-on-palo-alto-networks-globalprotect-devices/
π@malwr
Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as UTA...
https://www.volexity.com/blog/2024/05/15/detecting-compromise-of-cve-2024-3400-on-palo-alto-networks-globalprotect-devices/
π@malwr
Volexity
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices
Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as UTA0218. Volexity has conducted several additional incidentβ¦
2024-05-14: DarkGate activity
https://www.malware-traffic-analysis.net/2024/05/14/index.html
π@malwr
https://www.malware-traffic-analysis.net/2024/05/14/index.html
π@malwr
Tracking the Progression of Earth Hundun's Cyberespionage Campaign in 2024
This report describes how Waterbear and Deuterbear β two of the tools in Earth Hundun's arsenal β operate, based on a campaign from 2024.
https://www.trendmicro.com/en_us/research/24/e/earth-hundun-2.html
π@malwr
This report describes how Waterbear and Deuterbear β two of the tools in Earth Hundun's arsenal β operate, based on a campaign from 2024.
https://www.trendmicro.com/en_us/research/24/e/earth-hundun-2.html
π@malwr
Trend Micro
Tracking the Progression of Earth Hundun's Cyberespionage Campaign in 2024
This report describes how Waterbear and Deuterbear β two of the tools in Earth Hundun's arsenal β operate, based on a campaign from 2024.
π1
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs
https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/
π@malwr
ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs
https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/
π@malwr
Welivesecurity
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs
Talos releases new macOS open-source fuzzer
Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.
https://blog.talosintelligence.com/talos-releases-new-macos-fuzzer/
π@malwr
Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.
https://blog.talosintelligence.com/talos-releases-new-macos-fuzzer/
π@malwr
Cisco Talos
Talos releases new macOS open-source fuzzer
Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.
Hackers use Malicious OneNote files for Delivering Payloads to Victims
Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The malware aims to deliver malicious payloads like Qakbot, Emotet, and AsyncRAT. Attackers prefer lightweight malware for easier delivery, avoiding heavier files like EXE or Office 97-2003 files.
https://hackhunting.com/2024/05/17/hackers-use-malicious-onenote-files-for-delivering-payloads-to-victims/
π@malwr
Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The malware aims to deliver malicious payloads like Qakbot, Emotet, and AsyncRAT. Attackers prefer lightweight malware for easier delivery, avoiding heavier files like EXE or Office 97-2003 files.
https://hackhunting.com/2024/05/17/hackers-use-malicious-onenote-files-for-delivering-payloads-to-victims/
π@malwr
HACKHUNTING
Hackers use Malicious OneNote files for Delivering Payloads to Victims
Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The maβ¦
Mobile Malware Analysis Part 7 β Blackrock
https://8ksec.io/mobile-malware-analysis-part-7-blackrock/
π@malwr
https://8ksec.io/mobile-malware-analysis-part-7-blackrock/
π@malwr
8kSec
Mobile Malware Part 7: Blackrock Analysis | 8kSec
Analyze the Blackrock Android malware in Part 7 of the mobile malware series. Learn how it abuses accessibility services and overlays to steal data.
Bad Karma, No Justice: Void Manticore Destructive Activities in Israel
https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/
π@malwr
https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/
π@malwr
Check Point Research
Bad Karma, No Justice: Void Manticore Destructive Activities in Israel - Check Point Research
Introduction Since October 2023, Check Point Research (CPR) has actively monitored and hunted state-sponsored threats targeting Israeli organizations with destructive attacks using wipers and ransomware. Among these threats, Void Manticore (aka Storm-842)β¦
YARA is dead, long live YARA-X
https://blog.virustotal.com/2024/05/yara-is-dead-long-live-yara-x.html
π@malwr
https://blog.virustotal.com/2024/05/yara-is-dead-long-live-yara-x.html
π@malwr
Virustotal
YARA is dead, long live YARA-X
For over 15 years, YARA has been growing and evolving until it became an indispensable tool in every malware researcher's toolbox. Througho...
π1π€1
x-cod3r/Remote-administration-tools-archive: Here are +200 different rats some with source code
https://github.com/x-cod3r/Remote-administration-tools-archive?tab=readme-ov-file
π@malwr
https://github.com/x-cod3r/Remote-administration-tools-archive?tab=readme-ov-file
π@malwr
GitHub
GitHub - x-cod3r/Remote-administration-tools-archive: Here are +200 different rats some with source code
Here are +200 different rats some with source code - x-cod3r/Remote-administration-tools-archive
π1
Exploit PoC released for Zabbix Server SQL injection vulnerability β CVE-2024-22120
A critical time-based SQL injection vulnerability (CVE-2024-22120, severity 9.1) affects Zabbix Server versions 6.0.0 - 6.0.27, 6.0.28rc1, 6.4.0 - 6.4.12, 6.4.13rc1, 7.0.0alpha1 - 7.0.0beta1, and 7.0.0beta2. Exploitation allows privilege escalation to admin and potential remote code execution. A $3000 exploit code has been shared on GitHub. Users are advised to update.
https://hackhunting.com/2024/05/21/exploit-poc-released-for-zabbix-server-sql-injection-vulnerability-cve-2024-22120/
π@malwr
A critical time-based SQL injection vulnerability (CVE-2024-22120, severity 9.1) affects Zabbix Server versions 6.0.0 - 6.0.27, 6.0.28rc1, 6.4.0 - 6.4.12, 6.4.13rc1, 7.0.0alpha1 - 7.0.0beta1, and 7.0.0beta2. Exploitation allows privilege escalation to admin and potential remote code execution. A $3000 exploit code has been shared on GitHub. Users are advised to update.
https://hackhunting.com/2024/05/21/exploit-poc-released-for-zabbix-server-sql-injection-vulnerability-cve-2024-22120/
π@malwr
HACKHUNTING
Exploit PoC released for Zabbix Server SQL injection vulnerability β CVE-2024-22120
A critical time-based SQL injection vulnerability (CVE-2024-22120, severity 9.1) affects Zabbix Server versions 6.0.0 β 6.0.27, 6.0.28rc1, 6.4.0 β 6.4.12, 6.4.13rc1, 7.0.0alpha1 ββ¦
π4
Politically Charged Ransomware Weaponized as a File Destroyer
The SonicWall Capture Labs threat research team has been observing a growth of malware built using the Chaos ransomware builder. The sample we have analyzed here is built using this kit, however, it is not
https://blog.sonicwall.com/en-us/2024/05/politically-charged-ransomware-weaponized-as-a-file-destroyer/
π@malwr
The SonicWall Capture Labs threat research team has been observing a growth of malware built using the Chaos ransomware builder. The sample we have analyzed here is built using this kit, however, it is not
https://blog.sonicwall.com/en-us/2024/05/politically-charged-ransomware-weaponized-as-a-file-destroyer/
π@malwr
Dissecting Windows Malware Series β Explaining Rootkits: Practical Examples & Investigation Methods β Part 6
https://8ksec.io/dissecting-windows-malware-series-explaining-rootkits-practical-examples-investigation-methods-part-6/
π@malwr
https://8ksec.io/dissecting-windows-malware-series-explaining-rootkits-practical-examples-investigation-methods-part-6/
π@malwr
8kSec
Windows Malware Part 6: Rootkits | 8kSec
Explore rootkits and kernel internals in Part 6 of the Windows malware series. Learn practical rootkit investigation methods with examples.
From trust to trickery: Brand impersonation over the email attack vector
Cisco recently developed and released a new feature to detect brand impersonation in emails when adversaries pretend to be a legitimate corporation.
https://blog.talosintelligence.com/from-trust-to-trickery-brand-impersonation/
π@malwr
Cisco recently developed and released a new feature to detect brand impersonation in emails when adversaries pretend to be a legitimate corporation.
https://blog.talosintelligence.com/from-trust-to-trickery-brand-impersonation/
π@malwr
Cisco Talos
From trust to trickery: Brand impersonation over the email attack vector
Cisco recently developed and released a new feature to detect brand impersonation in emails when adversaries pretend to be a legitimate corporation.